首页> 外文期刊>Indian Journal of Science and Technology >Analysis of Various Intrusion Detection Systems with a Model for Improving Snort Performance
【24h】

Analysis of Various Intrusion Detection Systems with a Model for Improving Snort Performance

机译:使用提高Snort性能的模型分析各种入侵检测系统

获取原文
获取外文期刊封面目录资料

摘要

Objectives: To assess various Intrusion Detection Systems (IDS) against various types of attacks in different environments like Web, Enterprise, Cloud, etc. and to propose architecture for improving the Snort based IDS performance during typical attacks. Methods: Analytical approach was used to survey various research papers in this field of research. Findings: In this research, various approaches of IDS were analysed in various aspects like Detection Accuracy, False Alarm Rate, Scalability and Capability of detecting unknown attacks. Some approaches focused on particular type of issues while ignoring the others. This lead to performance degrading in several cases which is not tolerable in real time scenarios. Improvements: Among various studied approaches, we chose Snort based IDS to improve its performance in order to deploy in enterprise networks. Being an Open Source Software, Snort gives the flexibility to improve its functionality. We propose architecture to improve Snort's detection rate and to reduce the packet drops during critical attacks like Port Scanning, DoS, DDoS Attacks, etc.
机译:目标:评估各种入侵检测系统(IDS)在不同环境(例如Web,企业,云等)中针对各种类型的攻击,并提出用于在典型攻击过程中提高基于Snort的IDS性能的体系结构。方法:采用分析方法对该领域的各种研究论文进行调查。发现:在本研究中,从检测准确性,误报率,可伸缩性和检测未知攻击的能力等各个方面分析了IDS的各种方法。有些方法侧重于特定类型的问题,而忽略了其他方法。在某些情况下,这会导致性能下降,这在实时情况下是无法容忍的。改进:在研究的各种方法中,我们选择了基于Snort的IDS来改善其性能,以便在企业网络中进行部署。作为一个开源软件,Snort可以灵活地改进其功能。我们提出了一种架构,以提高Snort的检测率并减少严重攻击(例如端口扫描,DoS,DDoS攻击等)期间的数据包丢失。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号